The flaw, designated CVE-2025-5333 with a severe CVSS v4.0 score of 9.5, affects multiple versions of the widely-deployed endpoint management solution and has prompted immediate mitigation recommendations from security experts. CVE-2025-5333 (CVSS 9.5) affects Symantec Endpoint Management Suite 8.6.x-8.8, enabling unauthenticated remote code execution via port 4011. Primary mitigation involves ensuring firewalls block port 4011 on Notification Servers, effectively preventing remote exploitation. LRQA security researchers discovered the vulnerability during a Red Team assessment after identifying exposed processes on a hardened endpoint. Block port 4011 on firewalls - this port is unnecessary for normal Symantec operations according to Broadcom documentation. This allows attackers to craft malicious .NET objects that trigger arbitrary code execution when processed by the target server. Insecure .NET object deserialization in Altiris IRM component allows attackers to execute arbitrary code through crafted payloads.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 15 Jul 2025 07:45:18 +0000